Let an agent register itself
Some agents can’t open a browser sign-in. Those can ask for access on your behalf through auth.md: the agent registers with your email address, shows you a link and a six-digit code, and you approve it in Hydrant. Until you do, it has nothing. Not a read, not a key, not a foot in the door.
Agent sign-up is switched on separately, and it can be off. While it’s off, an agent that reads https://hydrant.dev/auth.md gets a 404 and has nothing to register with. If your agent can do the browser sign-in, Connect your agent works either way, and it’s the better route.
Before you start
Section titled “Before you start”- Your agent can’t do the browser sign-in. If it can, use the setup prompt instead. Both end at the same address,
https://hydrant.dev/api/mcp, and neither ever asks you for an API key. - A GitHub account whose verified primary email is the address you give the agent. Hydrant compares it with the primary email GitHub reports as verified, private or not. Any other address won’t match.
- New to Hydrant? That’s fine. The GitHub sign-in on the approval page creates your account, and you accept the Terms and Privacy Policy there like anyone signing up. Already have an account? Same sign-in; the agent becomes one more connection on it.
- A free slot. These connections share the workspace’s limit with keys and browser connections. See Plans and billing.
- Your role sets the ceiling. You choose read only or read and write, and the agent never gets more than you have.
- Give the agent your email address and ask it to register with Hydrant through
https://hydrant.dev/auth.md. - It shows you a link and a six-digit code. The code lasts 10 minutes. If it runs out, the agent can ask for a new one, with a new link: five codes in all, within an hour of the first.
- Open the link and sign in with GitHub.
- Read the page. An agent wants in. shows the name the agent gave itself (its word, not ours), when it registered and what it asks for at most.
- Type the code under Code from your agent. Only use a code an agent you’re running just showed you.
- Choose one workspace. Need two? Have the agent register twice. With no workspace yet, name your first one right there.
- Choose Read and write or Read only.
- Press Approve (Create and approve when you’re naming a new workspace), or Deny.
- Go back to the agent. It picks up your answer on its next check. Then, just like the setup prompt’s last step, it should call
get_workspaceand tell you the workspace name.
What you should see
Section titled “What you should see”- Approved. with an Open Settings › Agents button.
- Under Settings › Agents › Access, the connection shows the agent’s name in quotes, via auth.md, and “Unverified name” with its registration ID. It starts as “authorized, waiting for its first contact” and turns verified on its first request.
- Its work is credited as “name (agent; via you)”.
How long it lasts
Section titled “How long it lasts”The agent holds a one-hour pass and renews it itself, for 30 days from when it picked up your approval. There’s no refresh token behind it, so using it more doesn’t buy more time. After 30 days the row reads “Its 30-day approval ran out. Ask the agent to register again, then approve the new code.” A browser connection works differently: it stays connected as long as it’s used at least every 30 days.
If agent sign-up is switched off later, nothing is revoked. The row says “Agent sign-up is off, so it can’t renew.” Its access stops when its current pass runs out, and it renews again once sign-up is back, within those 30 days.
If it goes sideways
Section titled “If it goes sideways”- “Wrong account for this one.” The page shows the address the agent asked for, partly hidden. Press Use another account and sign in with the GitHub account it belongs to. Not yours at all? Close the tab; nothing happens.
- “We couldn’t confirm your GitHub primary email.” GitHub didn’t share a verified primary email at sign-in. Verify one on GitHub, then sign in again.
- “This code went stale.” It expired, or the agent asked for a newer one. Use the latest link and code it shows you. After an hour it has to register again.
- “That code’s done.” Five wrong tries. Ask the agent for a new code; it comes with a new link.
- “Agent sign-up is off.” The link approves nothing. Connect the agent the usual way: Connect your agent.
- Every slot is taken. The request stays open. Pick another workspace or revoke something you don’t use, then approve again.
- You denied it by mistake. Ask the agent to register again.
- You approved something you didn’t mean to. Revoke it under Settings › Agents. It loses access at once, its next renewal fails, and its recorded work stays. See Reconnect, expire, revoke.
- Someone else sent you the link. Close the tab. Whoever sent it gets whatever you approve.
- Everything else: When an agent gets stuck.